Latest CVE Feed
-
6.5
MEDIUMCVE-2020-9337
In GolfBuddy Course Manager 1.1, passwords are sent (with base64 encoding) via a GET request.... Read more
Affected Products : course_manager- Published: Feb. 26, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-9336
fauzantrif eLection 2.0 has XSS via the Admin Dashboard -> Settings -> Election -> "message if election is closed" field.... Read more
Affected Products : fauzantrif_election- Published: Feb. 22, 2020
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2020-9335
Multiple stored XSS vulnerabilities exist in the 10Web Photo Gallery plugin before 1.5.46 WordPress. Successful exploitation of this vulnerability would allow a authenticated admin user to inject arbitrary JavaScript code that is viewed by other users.... Read more
Affected Products : photo_gallery- Published: Feb. 25, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-9334
A stored XSS vulnerability exists in the Envira Photo Gallery plugin through 1.7.6 for WordPress. Successful exploitation of this vulnerability would allow a authenticated low-privileged user to inject arbitrary JavaScript code that is viewed by other use... Read more
- Published: Feb. 25, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2020-9332
ftusbbus2.sys in FabulaTech USB for Remote Desktop through 2020-02-19 allows privilege escalation via crafted IoCtl code related to a USB HID device.... Read more
Affected Products : usb_for_remote_desktop- Published: Jun. 17, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2020-9331
CryptoPro CSP through 5.0.0.10004 on 32-bit platforms allows Local Privilege Escalation (by local users with the SeChangeNotifyPrivilege right) because user-mode input is mishandled during process creation. An attacker can write arbitrary data to an arbit... Read more
Affected Products : csp- Published: Oct. 23, 2020
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2020-9330
Certain Xerox WorkCentre printers before 073.xxx.000.02300 do not require the user to reenter or validate LDAP bind credentials when changing the LDAP connector IP address. A malicious actor who gains access to affected devices (e.g., by using default cre... Read more
- Published: Feb. 21, 2020
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2020-9329
Gogs through 0.11.91 allows attackers to violate the admin-specified repo-creation policy due to an internal/db/repo.go race condition.... Read more
Affected Products : gogs- Published: Feb. 21, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2020-9327
In SQLite 3.31.1, isAuxiliaryVtabOperator allows attackers to trigger a NULL pointer dereference and segmentation fault because of generated column optimizations.... Read more
- Published: Feb. 21, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2020-9326
BeyondTrust Privilege Management for Windows and Mac (aka PMWM; formerly Avecto Defendpoint) 5.1 through 5.5 before 5.5 SR1 mishandles command-line arguments with PowerShell .ps1 file extensions present, leading to a DefendpointService.exe crash.... Read more
Affected Products : privilege_management_for_windows_and_mac- Published: Mar. 18, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2020-9325
Aquaforest TIFF Server 4.0 allows Unauthenticated Arbitrary File Download.... Read more
Affected Products : tiff_server- Published: Mar. 18, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2020-9324
Aquaforest TIFF Server 4.0 allows Unauthenticated SMB Hash Capture via UNC.... Read more
Affected Products : tiff_server- Published: Mar. 18, 2020
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2020-9323
Aquaforest TIFF Server 4.0 allows Unauthenticated File and Directory Enumeration via tiffserver/tssp.aspx.... Read more
Affected Products : tiff_server- Published: Mar. 18, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2020-9321
configurationwatcher.go in Traefik 2.x before 2.1.4 and TraefikEE 2.0.0 mishandles the purging of certificate contents from providers before logging.... Read more
Affected Products : traefik- Published: Mar. 16, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-9320
Avira AV Engine before 8.3.54.138 allows virus-detection bypass via a crafted ISO archive. This affects versions before 8.3.54.138 of Antivirus for Endpoint, Antivirus for Small Business, Exchange Security (Gateway), Internet Security Suite for Windows, P... Read more
- Published: Feb. 20, 2020
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2020-9318
Red Gate SQL Monitor 9.0.13 through 9.2.14 allows an administrative user to perform a SQL injection attack by configuring the SNMP alert settings in the UI. This is fixed in 9.2.15.... Read more
Affected Products : sql_monitor- Published: Feb. 20, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2020-9315
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x has Incorrect Access Control for admingui/version URIs in the Administration console, as demonstrated by unauthenticated read access to encryption keys. NOTE: a related support poli... Read more
Affected Products : iplanet_web_server- Published: May. 10, 2020
- Modified: Nov. 21, 2024
-
4.9
MEDIUMCVE-2020-9314
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x allows image injection in the Administration console via the productNameSrc parameter to an admingui URI. This issue exists because of an incomplete fix for CVE-2012-0516. NOTE: a r... Read more
Affected Products : iplanet_web_server- Published: May. 10, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-9311
In SilverStripe through 4.5, malicious users with a valid Silverstripe CMS login (usually CMS access) can craft profile information which can lead to XSS for other users through specially crafted login form URLs.... Read more
- Published: Jul. 15, 2020
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2020-9309
Silverstripe CMS through 4.5 can be susceptible to script execution from malicious upload contents under allowed file extensions (for example HTML code in a TXT file). When these files are stored as protected or draft files, the MIME detection can cause b... Read more
- Published: Jul. 15, 2020
- Modified: Nov. 21, 2024